Register a webhook endpoint for this merchant; the signing secret is returned once
Registers a webhook endpoint that receives only this merchant's events.
/v1/clients/{clientId}/webhook_endpointsRegisters a webhook endpoint that receives only this merchant's events. The signing secret is returned here and nowhere else. event_filters narrows what is delivered; omit it for every event the merchant can see. Needs authority over the client — membership of its organization, an API key bound to this client, or tenant staff holding clients:manage; anything else is refused not_client_member or insufficient_scope (403), and an unknown client client_not_found (404). A merchant-bound API key may register its own endpoints, which is the point; it still cannot touch the tenant-wide webhook surface. A missing body or a URL the service will not accept gives invalid_request (400).
Authorization
bearerAuth A tenant API key (sk_{env}_{id}_{secret}), a wallet user token, or an IdP access token. Which principal the credential resolves to decides the scopes it carries; see the authentication guide.
In: header
Path Parameters
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
curl -X POST "https://example.com/v1/clients/497f6eca-6276-4993-bfeb-53cbbbba6f08/webhook_endpoints" \ -H "Content-Type: application/json" \ -d '{ "url": "http://example.com" }'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "client_id": "5b3fa7ba-57d3-4017-a65b-d57dcd2db643", "url": "string", "event_filters": [ "string" ], "status": "string", "secret": "string", "created_at": "2019-08-24T14:15:22Z"}